2026 CVE Vulnerabilities

70,493 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2597HIGH7.5Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by...
CVE-2026-27773MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-27772CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-27767CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-27652HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25945CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-25851CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-25778HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25711HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-25114CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-25113CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-24731CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-22890MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-20895HIGH7.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to...
CVE-2026-20792CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-20791HIGH7.5Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-20781CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-20733MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-1585HIGH8.4An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 ma...
CVE-2026-3268MEDIUM4.3A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file...
CVE-2026-3265HIGH8.8A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unk...
CVE-2026-3264HIGH8.8A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this is...
CVE-2026-28280HIGH8.7osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exis...
CVE-2026-28279HIGH8.4osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `o...
CVE-2026-28276HIGH7.5Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now